Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 909226 (CVE-2023-25515, CVE-2023-25516) - <x11-drivers/nvidia-drivers-{470.199.02:0/470,525.125.06:0/525,535.54.03:0/535}: multiple vulnerabilities
Summary: <x11-drivers/nvidia-drivers-{470.199.02:0/470,525.125.06:0/525,535.54.03:0/53...
Status: CONFIRMED
Alias: CVE-2023-25515, CVE-2023-25516
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://nvidia.custhelp.com/app/answe...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-27 04:06 UTC by Ionen Wolkens
Modified: 2024-02-11 08:15 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ionen Wolkens gentoo-dev 2023-06-27 04:06:29 UTC
Fixed versions are already in-tree, will give it a bit then stable the new 0/470 and 0/525.

535.43.02 was already removed yesterday, and was never keyworded (beta), so no affected 0/535 versions were ever visible.

515.105.01 is likely affected but given nvidia is not reporting this it likely means it's EOL. It's now dropped from the tree. Likewise for 530.41.03 which was already dropped in yesterday's cleanups.

As usual 0/390 and 0/vulkan branches are permanently masked with a warning about security, so not considering them for these bugs.

CVE-2023-25515:
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure.

CVE-2023-25516:
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which may lead to information disclosure and denial of service.
Comment 1 Larry the Git Cow gentoo-dev 2023-07-03 07:25:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0cb763074fa03bd7d19e0e72e3ac10cacf188dac

commit 0cb763074fa03bd7d19e0e72e3ac10cacf188dac
Author:     Ionen Wolkens <ionen@gentoo.org>
AuthorDate: 2023-07-03 07:20:01 +0000
Commit:     Ionen Wolkens <ionen@gentoo.org>
CommitDate: 2023-07-03 07:24:31 +0000

    x11-drivers/nvidia-drivers: drop vuln 470.182.03-r2, 525.116.04-r2
    
    All done wrt bug #909226
    
    Bug: https://bugs.gentoo.org/909226
    Signed-off-by: Ionen Wolkens <ionen@gentoo.org>

 x11-drivers/nvidia-drivers/Manifest                |   9 -
 .../nvidia-drivers-470.182.03-r2.ebuild            | 500 ------------------
 .../nvidia-drivers-525.116.04-r2.ebuild            | 561 ---------------------
 3 files changed, 1070 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=428e8194939cc9d081ddddc197105057ef399522

commit 428e8194939cc9d081ddddc197105057ef399522
Author:     Ionen Wolkens <ionen@gentoo.org>
AuthorDate: 2023-07-03 07:19:28 +0000
Commit:     Ionen Wolkens <ionen@gentoo.org>
CommitDate: 2023-07-03 07:23:02 +0000

    x11-drivers/nvidia-drivers: stabilize 525.125.06 for amd64
    
    Bug: https://bugs.gentoo.org/909226
    Signed-off-by: Ionen Wolkens <ionen@gentoo.org>

 x11-drivers/nvidia-drivers/nvidia-drivers-525.125.06.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=029d2b225e4c6b9e445dc7748180936a6887b942

commit 029d2b225e4c6b9e445dc7748180936a6887b942
Author:     Ionen Wolkens <ionen@gentoo.org>
AuthorDate: 2023-07-03 07:19:11 +0000
Commit:     Ionen Wolkens <ionen@gentoo.org>
CommitDate: 2023-07-03 07:23:02 +0000

    x11-drivers/nvidia-drivers: stabilize 470.199.02 for amd64
    
    Bug: https://bugs.gentoo.org/909226
    Signed-off-by: Ionen Wolkens <ionen@gentoo.org>

 x11-drivers/nvidia-drivers/nvidia-drivers-470.199.02.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)